The OCC Bulletin 2013-29 (and its 2020 FAQ update) primarily governs third-party risk management for:
-
A
All U.S. publicly traded companies subject to SEC reporting
-
B
National banks and federal savings associations supervised by the Office of the Comptroller of the Currency
-
C
Technology companies that sell software to the federal government
-
D
Healthcare organizations subject to HIPAA privacy requirements